← Back to Feed
Siemens Desigo DXR and PXC Controllers
CVE-2026-59693
August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL
A denial-of-service vulnerability (CVE-2026-59693) in Siemens Desigo DXR and PXC controllers allows an attacker to send malformed BACnet packets, causing devices to stop responding. Affected firmware versions require a reset or reboot for recovery. Siemens has released updates to fix the issue.
Key Takeaways
- CVE-2026-59693 allows denial of service via malformed BACnet packets in Siemens Desigo controllers. Affected products include Desigo DXR2, PXC3, PXC4, and others below specific firmware versions. Recovery requires a manual device reset or reboot to restore normal BACnet functionality.